Overview

FlashAir provided by Toshiba Corporation does not require authentication on accepting a connection from STA side LAN when "Internet pass-thru Mode" is enabled.

Products Affected

Japan

FlashAir SD-WD/WC series Class 6 model with firmware version 1.00.04 and later

FlashAir SD-WD/WC series Class 10 model W-02 with firmware version 2.00.02 and later

FlashAir SD-WE series Class 10 model W-03

USA

FlashAir Class 6 model with firmware version 1.00.04 and later

FlashAir II Class 10 model W-02 series with firmware version 2.00.02 and later

FlashAir III Class 10 model W-03 series

Countries & Regions except Japan and USA

FlashAir Class 6 model with firmware version 1.00.04 and later

FlashAir W-02 series Class 10 model with firmware version 2.00.02 and later

FlashAir W-03 series Class 10 model

Description

FlashAir by Toshiba Corporation is a SDHC memory card which provides "Internet pass-thru Mode", allowing devices to access the internet while connecting to FlashAir. When configured in "Internet pass-thru Mode", FlashAir acts both as a station and as an access point.
When "Internet pass-thru Mode" is enabled, FlashAir does not require authentication on accepting a connection from STA (station) side LAN.

Impact

A remote unauthenticated attacker with access to STA side LAN can obtain files or data saved in the vulnerable product.
In addition, when FlashAir III / FlashAir W-03 series is configured to access/upload files or data by WebDAV without authentication, the files and data saved in the vulnerable product can be altered or an arbitrary Lua script can be executed.

Solution

Change default settings in the configuration
Before enabling "Internet pass thru Mode", change the default settings to require authentication to the FlashAir web server.
In FlashAir API, followings are provided. Refer to the respective instructions for more information.